DocumentCode
2097683
Title
Modeling networking protocols to test intrusion detection systems
Author
Luo, Song ; Marin, Gerald A.
Author_Institution
Dept. of Comput. Sci., Central Florida Univ., Orlando, FL, USA
fYear
2004
fDate
16-18 Nov. 2004
Firstpage
774
Lastpage
775
Abstract
Techniques for detecting previously unseen network intrusion attempts often depend on finding anomalous behavior in network traffic streams. Thus, intrusion detection systems generally require tuning to be effective in each new environment. It follows that researchers need to produce traffic backgrounds for laboratory testing that accurately reflect the characteristics of organizations of interest. To these they need to be able to add attacks under controlled conditions so that actual performance of new IDS techniques can be evaluated. The authors have been working towards such a realistic and flexible testing environment. In previous work we have used application protocol traffic generation techniques and confirmed some of the classical statistical distributions. The distributions of other protocols have been updated based on the analysis of current traffic. In This work hybrid and heavy-tailed modeling techniques are used to build a detailed model of FTP including session arrivals, bytes transferred, and idle times. The same techniques are being used for other protocols including HTTP.
Keywords
computer network management; performance evaluation; security of data; telecommunication security; telecommunication traffic; transport protocols; FTP; HTTP; IDS techniques; anomalous behavior; attacks; heavy-tailed modeling; hybrid techniques; idle times; intrusion detection systems; network traffic streams; networking protocol modeling; performance evaluation; session arrivals; testing environment; transferred bytes; Communication system traffic control; Computer networks; Internet; Intrusion detection; Protocols; Random variables; Statistical distributions; System testing; Telecommunication traffic; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, 2004. 29th Annual IEEE International Conference on
ISSN
0742-1303
Print_ISBN
0-7695-2260-2
Type
conf
DOI
10.1109/LCN.2004.80
Filename
1367321
Link To Document